These are the ATS keywords, credentials, and software terms that recur across current penetration tester job descriptions — organized so you can scan for what your resume is missing. Placement matters as much as presence: an ATS keyword buried in a skills list ranks lower than the same term used in context inside an experience bullet.
Title variants
- Penetration Tester
- Pen Tester
- Ethical Hacker
- Red Team Analyst
- Offensive Security Engineer
- Security Consultant
- Vulnerability Researcher
Certifications
- OSCP
- OSCE
- OSEP
- CEH
- GPEN
- GWAPT
- GXPN
- CREST CRT
- CREST CCT
- CompTIA PenTest+
Web application
- web application penetration testing
- OWASP Top 10
- Burp Suite
- API security testing
- XSS
- SQL injection
- IDOR
- SSRF
- business logic vulnerabilities
Network and infrastructure
- network penetration testing
- Nmap
- Metasploit
- Nessus
- OpenVAS
- internal testing
- external testing
- firewall bypass
Active Directory / Windows
- Active Directory attacks
- BloodHound
- SharpHound
- Kerberoasting
- Pass-the-Hash
- lateral movement
- privilege escalation
- Cobalt Strike
- PowerShell Empire
Red team
- red team
- adversary simulation
- C2 framework
- persistence
- evasion
- MITRE ATT&CK
- TTP
- purple team
Cloud pentesting
- AWS penetration testing
- Azure security testing
- cloud misconfiguration
- IAM abuse
Research
- CVE
- bug bounty
- HackerOne
- Bugcrowd
- responsible disclosure
- CTF
- TryHackMe
- HackTheBox
- exploit development
Long-tail phrases
- penetration tester resume examples
- how to write a pen tester resume
- OSCP resume
- ethical hacker cv
- red team resume
- cybersecurity offensive security resume
Pasting these terms into your resume verbatim without matching context can read as keyword stuffing to a human reviewer, even if it passes the ATS. The full Penetration Tester resume guide shows where each category belongs and how to work it into real experience bullets.